Skip to main content
Mallory
CriticalCISA KEVExploited in the wildPublic exploit

Unauthenticated OS Command Injection in GeoVision Devices

IdentifiersCVE-2024-6047CWE-78· Improper Neutralization of Special…

CVE-2024-6047 is an OS command injection vulnerability affecting certain end-of-life GeoVision devices. The provided content states that the devices fail to properly filter user input for a specific functionality, allowing unauthenticated remote attackers to inject and execute arbitrary system commands on the device. Supporting reporting indicates exploitation via the /DateSetting.cgi endpoint, with commands injected through the szSrvIpAddr parameter. This is consistent with improper neutralization of special elements in an OS command.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows unauthenticated remote code execution in the context of the affected device's operating environment by executing arbitrary system commands. In observed exploitation, attackers used the flaw to download and run a Mirai-family payload, enabling device compromise and botnet enrollment. More broadly, attackers could use the vulnerability to take control of the device, alter configuration, deploy malware, disrupt service, and use the device as a foothold for further activity.

Mitigation

If you can’t patch tonight, do this now.

If immediate replacement or patching is not possible, remove affected GeoVision devices from direct internet exposure, restrict access to the vulnerable web interface to trusted management networks only, and block access to the /DateSetting.cgi endpoint externally. Use network segmentation, firewall ACLs, and VPN-only administrative access. Monitor for suspicious requests targeting /DateSetting.cgi and the szSrvIpAddr parameter, and for post-exploitation behaviors such as unexpected command execution, outbound malware retrieval, or Mirai-like botnet activity. Given that the devices are end-of-life and exploitation has been reported, decommissioning is the strongest mitigation.

Remediation

Patch, then assume compromise.

Apply the vendor-provided fix if one is available for the affected GeoVision product. Because the content explicitly describes the affected devices as end-of-life, the preferred remediation is to decommission and replace impacted devices with supported models. If a patch exists for a specific supported branch, update immediately and verify that internet exposure to the vulnerable interface is removed where possible.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
GeovisionGv Ipcamd Gv Bx130 Firmwareoperating_system
GeovisionGv Ipcamd Gv Bx1500 Firmwareoperating_system
GeovisionGv Ipcamd Gv Cb220 Firmwareoperating_system
GeovisionGv Ipcamd Gv Ebl1100 Firmwareoperating_system
GeovisionGv Ipcamd Gv Efd1100 Firmwareoperating_system
GeovisionGv Ipcamd Gv Fd2410 Firmwareoperating_system
GeovisionGv Ipcamd Gv Fd3400 Firmwareoperating_system
GeovisionGv Ipcamd Gv Fe3401 Firmwareoperating_system
GeovisionGv Ipcamd Gv Fe420 Firmwareoperating_system
GeovisionGv-Bx130 Firmwareoperating_system
GeovisionGv-Bx1500hardware
GeovisionGv-Bx1500 Firmwareoperating_system
GeovisionGv-Cb220hardware
GeovisionGv-Cb220 Firmwareoperating_system
GeovisionGv-Dsp Lpr Firmwareoperating_system
GeovisionGv-Dsp Lpr V2hardware
GeovisionGv-Ebl1100hardware
GeovisionGv-Ebl1100 Firmwareoperating_system
GeovisionGv-Efd1100hardware
GeovisionGv-Efd1100 Firmwareoperating_system
GeovisionGv-Fd2410hardware
GeovisionGv-Fd2410 Firmwareoperating_system
GeovisionGv-Fd3400hardware
GeovisionGv-Fd3400 Firmwareoperating_system
GeovisionGv-Fd3401hardware
GeovisionGv-Fe3401 Firmwareoperating_system
GeovisionGv-Fe420hardware
GeovisionGv-Fe420 Firmwareoperating_system
GeovisionGv-Gm8186 Vs14 Firmwareoperating_system
GeovisionGv-Lx 4 V2hardware
GeovisionGv-Lx 4 V3hardware
GeovisionGv-Vs03hardware
GeovisionGv-Vs03 Firmwareoperating_system
GeovisionGv-Vs04ahardware
GeovisionGv-Vs04a Firmwareoperating_system
GeovisionGv-Vs04hhardware
GeovisionGv-Vs04h Firmwareoperating_system
GeovisionGv-Vs14hardware
GeovisionGv-Vs14 Firmwareoperating_system
GeovisionGv-Vs14 Vs14 Firmwareoperating_system
GeovisionGv-Vs21600 Firmwareoperating_system
GeovisionGv-Vs216xxhardware
GeovisionGv-Vs216xx Firmwareoperating_system
GeovisionGv-Vs2410hardware
GeovisionGv-Vs2410 Firmwareoperating_system
GeovisionGv-Vs2800 Firmwareoperating_system
GeovisionGv-Vs2820 Firmwareoperating_system
GeovisionGv-Vs28xxhardware
GeovisionGv-Vs28xx Firmwareoperating_system
GeovisionGvlx 4 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware2

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity16

Community discussion across Reddit, Mastodon, and other social sources.